
d0xing
@d00xing
ID: 3129600429
http://hackerone.com/d0xing 30-03-2015 18:56:58
798 Tweet
7,7K Followers
775 Following


Workshop "Demystifying the Server Side" slides presented at Ekoparty, Hackitvity Conf, and NoNameCon 2020 by Rajanish Pathak Rahul Maini and me. docs.google.com/presentation/dโฆ


Recently Justin Gardner sparked a discussion about exploiting blind SSRFs. At Assetnote, we've collected some information together and have created a Glossary of Blind SSRF Chains which can be found here: blog.assetnote.io/2021/01/13/bliโฆ - we hope people can use it as a reference!






New attacks on OAuth: SSRF by design and Session Poisoning by Michael Stepankin portswigger.net/research/hiddeโฆ




HTTP/2: The Sequel is Always Worse by James Kettle portswigger.net/research/http2





